VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 189 of 1,043
  • CVE-2024-51818CriJan 21, 2025
    risk 0.62cvss 9.3epss 0.16

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.

  • CVE-2023-29119CriNov 5, 2024
    risk 0.62cvss 9.6epss 0.00

    Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.

  • CVE-2023-29118CriNov 5, 2024
    risk 0.62cvss 9.6epss 0.00

    Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.

  • CVE-2024-3922CriJun 13, 2024
    risk 0.62cvss 10.0epss 0.53

    The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2024-29822HigMay 31, 2024
    risk 0.62cvss 8.8epss 0.64

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

  • CVE-2024-5315CriMay 24, 2024
    risk 0.62cvss 9.1epss 0.35

    Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters …

  • CVE-2024-33546CriApr 29, 2024
    risk 0.62cvss 9.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.

  • CVE-2023-28838CriApr 5, 2023
    risk 0.62cvss 9.6epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL Injection vulnerability allow users with access rights to statistics or reports to extract all data from database and, in some cases, write a webshell…

  • CVE-2023-23492HigJan 20, 2023
    risk 0.62cvss 8.8epss 0.57

    The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

  • CVE-2022-38490CriJan 10, 2023
    risk 0.62cvss 9.6epss 0.01

    An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue.

  • CVE-2022-23305CriJan 18, 2022
    risk 0.62cvss 9.8epss 0.67

    By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering…

  • CVE-2020-7471CriFeb 3, 2020
    risk 0.62cvss 9.8epss 0.66

    Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a…

  • CVE-2020-5192HigJan 6, 2020
    risk 0.62cvss 8.8epss 0.17

    PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.

  • CVE-2018-20556HigMar 21, 2019
    risk 0.62cvss 8.8epss 0.19

    SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.

  • CVE-2017-15367CriMar 7, 2018
    risk 0.62cvss 9.8epss 0.23

    Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.

  • CVE-2026-15623CriAug 17, 2026
    risk 0.61cvss —epss 0.00

    A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability…

  • CVE-2026-58048CriJul 31, 2026
    risk 0.61cvss —epss 0.01

    Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

  • CVE-2026-6881CriJul 28, 2026
    risk 0.61cvss —epss 0.00

    A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions;…

  • CVE-2024-46636CriApr 27, 2026
    risk 0.61cvss 9.4epss 0.00

    NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category parameter

  • CVE-2026-39109CriApr 20, 2026
    risk 0.61cvss 9.4epss 0.01

    SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve…